CVE-2020-10188
critical · 9.8utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
9.8
CVSS
74.3%
EPSS (exploit prob.)
99th
EPSS percentile
2020-03-06
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-120
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| netkit_telnet_project | netkit_telnet | <= 0.17 |
| fedoraproject | fedora | 30 |
| fedoraproject | fedora | 31 |
| fedoraproject | fedora | 32 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| arista | eos | <= 4.20.15 |
| arista | eos | >= 4.21.0, <= 4.21.10m |
| arista | eos | >= 4.22, <= 4.22.4m |
| arista | eos | >= 4.23, <= 4.23.3m |
| arista | eos | 4.24.0f |
| oracle | communications_performance_intelligence_center | 10.4.0.2 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3 |
| juniper | junos | 12.3r12 |
Check a specific version with /api/v1/cve/match.
References
- https://appgateresearch.blogspot.com/2020/02/bravestarr-fedora-31-netkit-telnetd_28.html
- https://github.com/krb5/krb5-appl/blob/d00cd671dfe945791b33d4f1f6a5c57ae1667ef8/telnet/telnetd/utility.c#L205-L216
- https://lists.debian.org/debian-lts-announce/2020/05/msg00012.html
- https://lists.debian.org/debian-lts-announce/2020/08/msg00038.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7FMTRRQTYKWZD2GMXX3GLZV46OLPCLVK/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HLU6FL24BSQQEB2SJC26NLJ2MANQDA7M/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K3VJ6V2Z3JRNJOBVHSOPMAC76PSSKG6A/
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-telnetd-EFJrEzPx
- https://www.arista.com/en/support/advisories-notices/security-advisories/10702-security-advisory-48
- https://www.oracle.com/security-alerts/cpuApr2021.html
- http://www.openwall.com/lists/oss-security/2026/01/20/8
- https://appgateresearch.blogspot.com/2020/02/bravestarr-fedora-31-netkit-telnetd_28.html
- https://github.com/krb5/krb5-appl/blob/d00cd671dfe945791b33d4f1f6a5c57ae1667ef8/telnet/telnetd/utility.c#L205-L216
- https://lists.debian.org/debian-lts-announce/2020/05/msg00012.html
- https://lists.debian.org/debian-lts-announce/2020/08/msg00038.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7FMTRRQTYKWZD2GMXX3GLZV46OLPCLVK/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HLU6FL24BSQQEB2SJC26NLJ2MANQDA7M/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K3VJ6V2Z3JRNJOBVHSOPMAC76PSSKG6A/
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-telnetd-EFJrEzPx
- https://www.arista.com/en/support/advisories-notices/security-advisories/10702-security-advisory-48
- https://www.oracle.com/security-alerts/cpuApr2021.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-10188